drop multiple linux log files · merge auth.log syslog kern.log apache access logs · unified timeline · correlation · runs locally
Worker auto-picks a parser from the first ~120 lines per file (syslog RFC3164/5424, journal JSON, apache combined, audit key=value, bash timestamps, mysql/postgres errors, dmesg brackets). Cap ~150k merged events.
drop auth.log syslog kern.log apache access logs journal export